Files
pj 7c845ff498 ci: declare least-privilege permissions
none of the three declared any, so each got the repository default.
release.yml and docs.yml already do this. all three only check out,
build, test and upload artifacts.
2026-08-15 12:46:49 +05:30

134 lines
4.1 KiB
YAML

name: ci
on:
# Runs on PRs (opened / synchronize / reopened, which are the defaults) and
# manual dispatch only. We deliberately don't run on direct pushes to master:
# master is PR-merge-only, and PR validation already covers the merge
# commit via the `synchronize` event on the PR branch.
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache: true
- name: Set up JDK 17
uses: actions/setup-java@v4
with:
distribution: temurin
java-version: "17"
- name: Set up Android SDK
uses: android-actions/setup-android@v3
- name: Set up Node 22
uses: actions/setup-node@v4
with:
node-version: "22"
cache: npm
cache-dependency-path: pkg/spec/package-lock.json
- name: Set up bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.13"
- name: Cache bun store
uses: actions/cache@v4
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('replay-ui/bun.lock') }}
restore-keys: |
bun-${{ runner.os }}-
# The token is what stops this step flaking: without it the action pulls
# buf's release tarball from github.com anonymously, on the shared runner
# IP's rate limit, and a throttled connection shows up as `socket hang
# up` after three retries. The version is the action's own default, made
# explicit so a new action release cannot move the buf we build with.
- name: Install buf
uses: bufbuild/buf-setup-action@a47c93e0b1648d5651a065437926377d060baa99 # v1.50.0
with:
version: "1.50.0"
github_token: ${{ secrets.GITHUB_TOKEN }}
- name: Install protoc plugins
run: |
go install google.golang.org/protobuf/cmd/protoc-gen-go@latest
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
gradle-${{ runner.os }}-
- name: Bootstrap
run: make bootstrap
- name: Lint proto
run: buf lint
- name: Go vet
run: go vet ./...
- name: Run tests
run: make test
browser:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Go
uses: actions/setup-go@v5
with:
go-version-file: go.mod
cache: true
# Pin stable: the action's default (latest) pulls a dev Chromium whose
# remote-debugging socket is flaky under the driver, even though the
# browser otherwise launches headless.
- name: Set up Chrome
uses: browser-actions/setup-chrome@v1
with:
chrome-version: stable
# Ubuntu 24.04 (current ubuntu-latest) restricts unprivileged user
# namespaces via AppArmor, which stops headless Chrome from starting even
# with --no-sandbox: the process launches but never opens its DevTools
# socket. Re-enable them so the driver's Chrome can come up.
- name: Allow Chrome under unprivileged user namespaces
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
# Fail here with Chrome's own stderr if the browser can't launch, instead
# of letting the driver report an opaque DevTools timeout downstream.
- name: Verify headless Chrome starts
run: |
chrome --version
chrome --headless --no-sandbox --disable-gpu --disable-dev-shm-usage \
--dump-dom 'data:text/html,<title>ok</title>'
- name: Drive web fixtures through headless Chrome
run: make test-browser